<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Hi Scott,</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
So I have taken over administration of our Shibb instance from a former colleague and I am following our documentation for upgrading, some of which is slightly different as its Puppet managed. Comparing to instructions found at
<a href="https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631513/Upgrading#Non-Windows-Upgrade" id="LPNoLPOWALinkPreview">
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631513/Upgrading#Non-Windows-Upgrade</a> which I'm sure you are familiar with I am doing the same:</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<span class="tabs2_section tabs2_section_0 tabs2_section0 " data-header-only="false" data-section-id="45e77fba7f00000127eda49aeb02bfa6"><span data-header-only="false" class="section sn-stream-section"><span class="sn-widget-textblock-body sn-widget-textblock-body_formatted">[root@srv01352
(DEV) shibboleth-identity-provider-4.2.1]# ./bin/install.sh <br>
Buildfile: /root/shibboleth-identity-provider-4.2.1/bin/build.xml <br>
<br>
install: <br>
Source (Distribution) Directory (press <enter> to accept default): [/root/shibboleth-identity-provider-4.2.1] ?
<br>
<br>
Installation Directory: [/opt/shibboleth-idp] ? <br>
/srv/shibboleth-idp <br>
WARN - Unable to find property resource '/srv/shibboleth-idp/credentials/secrets.properties' (check idp.additionalProperties?)
<br>
Update from version 4.0.1 to version 4.2.1 <br>
Rebuilding /srv/shibboleth-idp/war/idp.war, Version 4.2.1 <br>
Initial populate from /srv/shibboleth-idp/dist/webapp to /srv/shibboleth-idp/webpapp.tmp
<br>
Overlay from /srv/shibboleth-idp/edit-webapp to /srv/shibboleth-idp/webpapp.tmp <br>
Creating war file /srv/shibboleth-idp/war/idp.war <br>
<br>
BUILD SUCCESSFUL <br>
Total time: 39 seconds <br>
</span></span></span></div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Is that not an upgrade? configuration files such as attribute-resolver.xml, attribute-filter.xml, saml-nameid.xml etc in the installation directory /srv/shibboleth-idp/ which is where 4.0.1 was running are not changed so I assume this is an upgrade and not
install.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
I also looked at <a href="https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1469908146/Example+4.1+Upgrade" id="LPNoLPOWALinkPreview_1">
https://shibboleth.atlassian.net/wiki/spaces/KB/pages/1469908146/Example+4.1+Upgrade</a> and it seems like it should be a straightforward upgrade.<br>
</div>
<br>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Thanks</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Nilan<br>
</div>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_1"></div>
<br>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> Cantor, Scott <cantor.2@osu.edu><br>
<b>Sent:</b> 22 June 2022 12:53<br>
<b>To:</b> Nilan Morjaria-Patel <N.Morjaria-Patel@soton.ac.uk>; Shib Users <users@shibboleth.net><br>
<b>Subject:</b> Re: Upgrade from v4.0.1 to v4.2.1 - InvalidNameIDPolicy</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">CAUTION: This e-mail originated outside the University of Southampton.<br>
<br>
On 6/22/22, 4:54 AM, "Nilan Morjaria-Patel" <N.Morjaria-Patel@soton.ac.uk> wrote:<br>
<br>
> Hi Scott, So <a href="https://play01982.soton.ac.uk/shibboleth">https://play01982.soton.ac.uk/shibboleth</a> is the entityID of a test SP. Swapping out the upgraded<br>
> IDP for a non-upgraded IDP and it works fine, no InvalidNameIDPolicy error. So something I have missed in the<br>
> Release notes that causes this perhaps? Any tips to diagnose, perhaps put into debug?<br>
<br>
Then your upgraded IdP has a different configuration than the original and supports the requested NameIDFormat, it's that simple. And that means you didn't in fact upgrade at all, and there's really not much you could say that would convince me otherwise, given
that virtually every question on this list starts or ends with "I didn't actually upgrade, I installed from scratch."<br>
<br>
-- Scott<br>
<br>
<br>
</div>
</span></font></div>
</body>
</html>